Customize Tawk.to Widget Security & Risk Analysis

wordpress.org/plugins/customize-tawk-to-widget

This plugin allows you to customize the Tawk.to widget.

400 active installs v1.3.7 PHP 7.0+ WP 3.0.0+ Updated May 3, 2025
chatchatbotcustomizetawk-totawkto
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Customize Tawk.to Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Customize Tawk.to Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The plugin "customize-tawk-to-widget" v1.3.7 exhibits a generally good security posture with several positive indicators. Notably, it utilizes prepared statements for all its SQL queries, has a high percentage of properly escaped outputs, and no known vulnerabilities or CVEs in its history. The absence of dangerous functions, file operations, and critical or high-severity taint flows further contributes to its perceived safety. However, there are significant concerns regarding its attack surface. The presence of 4 AJAX handlers, with 2 of them lacking authentication checks, represents a direct pathway for potential exploitation if not properly secured by the WordPress environment. This oversight in authentication for some AJAX endpoints is the primary security weakness identified in the static analysis. The plugin also only implements nonce checks on 2 of its entry points, which could be insufficient given the number of AJAX handlers.

Key Concerns

  • AJAX handlers without auth checks
  • Limited nonce checks on entry points
Vulnerabilities
None known

Customize Tawk.to Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Customize Tawk.to Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
21 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

78% escaped27 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
customise_tawkto_ads (inc\main.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Customize Tawk.to Widget Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_customize_tawk_to_widget_saveinc\main.php:33
noprivwp_ajax_customize_tawk_to_widget_saveinc\main.php:34
authwp_ajax_customise_tawkto_adsinc\main.php:41
noprivwp_ajax_customise_tawkto_adsinc\main.php:42
WordPress Hooks 6
actionadmin_noticescustomize-tawk-to-widget.php:56
actionplugins_loadedinc\main.php:18
actionwp_enqueue_scriptsinc\main.php:29
actionadmin_enqueue_scriptsinc\main.php:31
actionwp_footerinc\main.php:35
actionadmin_menuinc\main.php:37
Maintenance & Trust

Customize Tawk.to Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMay 3, 2025
PHP min version7.0
Downloads12K

Community Trust

Rating60/100
Number of ratings2
Active installs400
Developer Profile

Customize Tawk.to Widget Developer Profile

adeleyeayodeji

5 plugins · 1K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Customize Tawk.to Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/customize-tawk-to-widget/assets/css/style.css/wp-content/plugins/customize-tawk-to-widget/assets/js/main.js
Script Paths
/wp-content/plugins/customize-tawk-to-widget/assets/js/main.js
Version Parameters
customize-tawk-to-widget/assets/css/style.css?ver=customize-tawk-to-widget/assets/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
advancetawktocustomise-style
JS Globals
advancetawktocustomise
REST Endpoints
/wp-json/customize-tawk-to-widget-save
FAQ

Frequently Asked Questions about Customize Tawk.to Widget